Fortinet white logo
Fortinet white logo

Administration Guide

SD-WAN Overlay-as-a-Service

SD-WAN Overlay-as-a-Service

SD-WAN Overlay-as-a-Service (OaaS) is supported through a license displayed as SD-WAN Overlay as a Service on the System > FortiGuard page. Each FortiGate used by the FortiCloud Overlay-as-a-Service portal must have this license applied to it.

To view the status of the OaaS license in the GUI:
  1. Go to System > FortiGuard.

  2. Expand License Information. The SD-WAN Overlay as a Service license status is listed as:

    • Licensed: OaaS is currently licensed and will expire on the provided date.

    • Expires Soon: OaaS is currently licensed but will expire soon on the provided date.

    • Expired: The OaaS license has already expired on the provided date.

    • Not Licensed: OaaS has not been licensed.

To view the status of the OaaS license in the CLI:
  1. Verify that the entitlement can be updated:

    Note

    The SD-WAN Overlay-as-a-Service license is listed as SWOS in the CLI.

    # diagnose test update info
    
    System contracts:
        FMWR,Wed Dec 20 16:00:00 2023
        SPAM,Wed Dec 20 16:00:00 2023
        SBCL,Wed Dec 20 16:00:00 2023
        SWNO,Wed Dec 20 16:00:00 2023
        SWNM,Wed Sep 27 17:00:00 2023
        SWOS,Mon Aug 14 17:00:00 2023
        SPRT,Wed Dec 20 16:00:00 2023
        SDWN,Sun Dec 10 16:00:00 2023
        SBCL,Wed Dec 20 16:00:00 2023
        SBEN,Wed Dec 20 16:00:00 2023
  2. Verify that the expiration date log can be generated:

    # execute log display
    
    1: date=2023-08-10 time=00:00:01 eventtime=1691650800645347120 tz="-0700" logid="0100020138" type="event" subtype="system" level="warning" vd="root" logdesc="FortiGuard SD-WAN Overlay as a Service license expiring" msg="FortiGuard SD-WAN Overlay Service license will expire in 4 day(s)"

To ensure FortiGate spoke traffic remains uninterrupted when configuration is orchestrated from the SD-WAN Overlay-as-a-Service (OaaS), support for an OaaS agent on the FortiGate is available. The OaaS agent communicates with the OaaS controller in FortiCloud, validates and compares the FortiOS configuration, and applies the FortiOS configuration to the FortiGate as a transaction when it has been orchestrated from the OaaS portal. Secure communication between the OaaS agent and the OaaS controller is achieved using the FGFM management tunnel.

If any configuration change fails to be applied, then the OaaS agent rolls back all configuration changes that were orchestrated. The OaaS status can be acquired using get oaas status.

To determine the status of OaaS:
# get oaas status
Account ID: 78992
Account: admin@domain.com
Site: site1
Configuration version: 4
Configuration sync status: SUCCESS
    Target version: 4
    Task ID: xxxxxxxxx
    Error:

SD-WAN Overlay-as-a-Service

SD-WAN Overlay-as-a-Service

SD-WAN Overlay-as-a-Service (OaaS) is supported through a license displayed as SD-WAN Overlay as a Service on the System > FortiGuard page. Each FortiGate used by the FortiCloud Overlay-as-a-Service portal must have this license applied to it.

To view the status of the OaaS license in the GUI:
  1. Go to System > FortiGuard.

  2. Expand License Information. The SD-WAN Overlay as a Service license status is listed as:

    • Licensed: OaaS is currently licensed and will expire on the provided date.

    • Expires Soon: OaaS is currently licensed but will expire soon on the provided date.

    • Expired: The OaaS license has already expired on the provided date.

    • Not Licensed: OaaS has not been licensed.

To view the status of the OaaS license in the CLI:
  1. Verify that the entitlement can be updated:

    Note

    The SD-WAN Overlay-as-a-Service license is listed as SWOS in the CLI.

    # diagnose test update info
    
    System contracts:
        FMWR,Wed Dec 20 16:00:00 2023
        SPAM,Wed Dec 20 16:00:00 2023
        SBCL,Wed Dec 20 16:00:00 2023
        SWNO,Wed Dec 20 16:00:00 2023
        SWNM,Wed Sep 27 17:00:00 2023
        SWOS,Mon Aug 14 17:00:00 2023
        SPRT,Wed Dec 20 16:00:00 2023
        SDWN,Sun Dec 10 16:00:00 2023
        SBCL,Wed Dec 20 16:00:00 2023
        SBEN,Wed Dec 20 16:00:00 2023
  2. Verify that the expiration date log can be generated:

    # execute log display
    
    1: date=2023-08-10 time=00:00:01 eventtime=1691650800645347120 tz="-0700" logid="0100020138" type="event" subtype="system" level="warning" vd="root" logdesc="FortiGuard SD-WAN Overlay as a Service license expiring" msg="FortiGuard SD-WAN Overlay Service license will expire in 4 day(s)"

To ensure FortiGate spoke traffic remains uninterrupted when configuration is orchestrated from the SD-WAN Overlay-as-a-Service (OaaS), support for an OaaS agent on the FortiGate is available. The OaaS agent communicates with the OaaS controller in FortiCloud, validates and compares the FortiOS configuration, and applies the FortiOS configuration to the FortiGate as a transaction when it has been orchestrated from the OaaS portal. Secure communication between the OaaS agent and the OaaS controller is achieved using the FGFM management tunnel.

If any configuration change fails to be applied, then the OaaS agent rolls back all configuration changes that were orchestrated. The OaaS status can be acquired using get oaas status.

To determine the status of OaaS:
# get oaas status
Account ID: 78992
Account: admin@domain.com
Site: site1
Configuration version: 4
Configuration sync status: SUCCESS
    Target version: 4
    Task ID: xxxxxxxxx
    Error: